All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-33017
CRITICALKEVpublished 2026-03-20 05:16 UTC · 5 months ago · modified 2026-06-17 10:36 UTC
9.3
CVSS / 10
// description
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
// required action (CISA KEV)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
added 2026-03-25 00:00 UTC
// weaknesses (CWE)
- CWE-94
- CWE-95
- CWE-306
// references (7)
- https://github.com/advisories/GHSA-rvqx-wpfh-mfx7
- https://github.com/langflow-ai/langflow/commit/73b6612e3ef25fdae0a752d75b0fabd47328d4f0
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx
- https://github.com/langflow-ai/langflow/releases/tag/1.8.2
- https://medium.com/@aviral23/cve-2026-33017-how-i-found-an-unauthenticated-rce-in-langflow-by-reading-the-code-they-already-dc96cdce5896